CVE-2026-63623

NameCVE-2026-63623
DescriptionA flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libvirt (PTS)bullseye7.0.0-3+deb11u3vulnerable
bullseye (security)7.0.0-3+deb11u4vulnerable
bookworm9.0.0-4+deb12u2vulnerable
trixie11.3.0-3+deb13u2vulnerable
forky, sid12.6.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libvirtsource(unstable)12.6.0-1

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2513066
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825 (v12.6.0-rc2)

Search for package or bug name: Reporting problems